John Web3
14 posts

John Web3 retweetledi

We should not allow this to become the new norm in security research. This must change.
gist.github.com/marikravets/28…
#BugBounty #CryptoSecurity #Web3 #SecurityResearch
@cantinaxyz @MonadOfficvn @monad @bountywriteups @VitalikButerin
English
John Web3 retweetledi
John Web3 retweetledi

⚠️A critical vulnerability (GHSA-vjh7-7g9h-fjfh) has been discovered in the widely-used elliptic encryption library.
😈Attackers can exploit this flaw by crafting specific inputs to extract private keys with just a single signature, potentially compromising digital assets or identity credentials.
✍️In our latest article, we break down the vulnerability—its root cause, impact, and how to mitigate the risks.
❤️Special thanks to @Rabby_io for providing the vulnerability intelligence.
🔗Read the full analysis here:
slowmist.medium.com/private-key-le…
English
John Web3 retweetledi

Bybit (@Bybit_Official) has received $172.5M in loans from various exchanges/institutions to manage customer withdrawals in the past 7 hours, including:
• 40,000 $ETH ($107M) from Bitget (@bitgetglobal)
• 12,652 $stETH ($33.9M) from a #MEXC’s hot wallet
• 11,800 $ETH ($31.6M) from a #Binance’s hot wallet
Follow @spotonchain and track the related entities in the recent #Bybit hack at:
1/ Bybit Exploiter entity: platform.spotonchain.ai/en/entity/2440
2/ Bybit’s Cold wallet: platform.spotonchain.ai/en/profile?add…

Spot On Chain@spotonchain
ℹ️ℹ️ Updated: - A hacker has compromised $1.4B. - The hacker is making large transfers of 10K ETH per address right now. - At least $200M $USDT was moved from Bybit’s cold wallet to its hot wallet in the past 30 minutes —unclear if it’s for user withdrawals or an ETH buyback. Most of the compromised funds are in $ETH. ETH price dropped 3% but quickly recovered after the news. - On-chain data shows the $1.4B loss is just 8.64% of their $16.2B reserves, meaning they can technically cover it. Withdrawals from Bybit are still functioning despite a significant surge in demand.
English
John Web3 retweetledi

Update on Safe{Wallet} Restart
The Safe{Wallet} UI displayed the correct-appearing transaction information according to ByBit, yet a malicious transaction that had all valid signatures was executed onchain. Our investigation so far shows:
• No codebase breach found: The Safe codebase was checked thoroughly, and no evidence of a breach or modification was found.
• No malicious dependencies identified: No signs of a malicious dependency in the Safe codebase affecting the transaction flow (i.e. supply-chain attack).
• No unauthorised access to the infrastructure was detected in the logs.
• No other Safe address has been affected
As stated earlier, we have paused Safe{Wallet} functionalities temporarily to ensure absolute confidence in our platform’s security. Although our investigation shows no evidence that the Safe{Wallet} frontend itself was compromised, we’re conducting a thorough review.
Some of the actions include:
• Reviewing all of our service configurations
• Rotating all our infrastructure credentials
• Rebuilding our containers and reapply all our configurations
• Conducting a codebase audit with external security researchers
We are committed to bringing Safe{Wallet} back up as soon as possible.
English

We’ve uncovered brand new, exclusive insights into the CoinPoker #hack—featuring details from #Fireblocks and other sources that shed light on this $2M breach.
📥 Get your copy: cyvers.ai/coinpokers-hac…
Our #CoinPoker case study breaks down the attack step-by-step, from the exploited loopholes to key takeaways every platform needs to know.
#Web3 #cybersecuritytips #Casestudy #CryptoNews
English

@HendikC61588 @indodax @frshzrnmln Nooo your balance is not safe
You guys have been hacked @indodax stop lying to your people
English

Halo Member INDODAX,
Kami ingin menginformasikan bahwa team security kami menemukan potensi indikasi keamanan pada platform kami.
Saat ini, kami sedang melakukan pemeliharaan menyeluruh untuk memastikan seluruh sistem beroperasi dengan baik. Selama proses pemeliharaan ini, platform web dan aplikasi INDODAX sementara tidak dapat diakses. Namun jangan khawatir, dapat kami pastikan bahwa saldo Anda tetap 100% aman baik secara kripto maupun rupiah.
Kami berterima kasih atas kesabaran dan kepercayaan yang telah Anda berikan. Proses ini kami lakukan demi menjaga keamanan dan kenyamanan transaksi Anda. Kami akan segera memberikan pembaruan informasi lanjutan setelah investigasi selesai dilakukan.
Salam,
INDODAX – Indonesia Bitcoin & Crypto Exchange

Indonesia

@danrobinson Almost 4 years ago now we wrote this on redistribution
medium.com/flashbots/fron…

English








